CVE-2016-8688
published 2017-02-15CVE-2016-8688: The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of…
PriorityP420medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.98%
78.3th percentile
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libarchive | < libarchive 3.2.1-5 (bookworm) | libarchive 3.2.1-5 (bookworm) |
| libarchive | libarchive | — | — |
| libarchive | libarchive | >= 0 < 3.2.1-5 | 3.2.1-5 |
| libarchive | libarchive | >= 0 < 3.2.1-5 | 3.2.1-5 |
| libarchive | libarchive | >= 0 < 3.2.1-5 | 3.2.1-5 |
| libarchive | libarchive | >= 0 < 3.2.1-5 | 3.2.1-5 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.4 | 3.1.2-7ubuntu2.4 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.3 | 3.1.2-11ubuntu0.16.04.3 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jf7m-wjh4-58hv: The mtree bidder in libarchive 3
ghsa_unreviewed·2022-05-14
CVE-2016-8688 [MEDIUM] CWE-125 GHSA-jf7m-wjh4-58hv: The mtree bidder in libarchive 3
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
OSV
libarchive vulnerabilities
osv·2017-03-09·CVSS 7.5
CVE-2016-5418 [HIGH] libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled hardlink entries when
extracting archives. A remote attacker could possibly use this issue to
overwrite arbitrary files. (CVE-2016-5418)
Christian Wressnegger, Alwin Maier, and Fabian Yamaguchi discovered that
libarchive incorrectly handled filename lengths when writing ISO9660
archives. A remote attacker could use this issue to cause libarchive to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6250)
Alexander Cherepanov discovered that libarchive incorrectly handled
recursive decompressions. A remote attacker could possibly use this issue
to cause libarchive to hang, resulting in a de
OSV
CVE-2016-8688: The mtree bidder in libarchive 3
osv·2017-02-15·CVSS 5.5
CVE-2016-8688 [MEDIUM] CVE-2016-8688: The mtree bidder in libarchive 3
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
Ubuntu
libarchive vulnerabilities
vendor_ubuntu·2017-03-09·CVSS 7.5
CVE-2016-5418 [HIGH] libarchive vulnerabilities
Title: libarchive vulnerabilities
Summary: libarchive could be made to crash, overwrite files, or run programs as your
login if it opened a specially crafted file.
It was discovered that libarchive incorrectly handled hardlink entries when
extracting archives. A remote attacker could possibly use this issue to
overwrite arbitrary files. (CVE-2016-5418)
Christian Wressnegger, Alwin Maier, and Fabian Yamaguchi discovered that
libarchive incorrectly handled filename lengths when writing ISO9660
archives. A remote attacker could use this issue to cause libarchive to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-6250)
Alexander Cherepanov discovered that libarchive in
Red Hat
libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c)
vendor_redhat·2016-09-15·CVSS 5.5
CVE-2016-8688 [MEDIUM] CWE-131 libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c)
libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c)
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: libarchive (Red Hat Enterprise Linux 6) - Not affected
Package: libarchive (Red Hat
Debian
CVE-2016-8688: libarchive - The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when exte...
vendor_debian·2016·CVSS 5.5
CVE-2016-8688 [MEDIUM] CVE-2016-8688: libarchive - The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when exte...
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
Scope: local
bookworm: resolved (fixed in 3.2.1-5)
bullseye: resolved (fixed in 3.2.1-5)
forky: resolved (fixed in 3.2.1-5)
sid: resolved (fixed in 3.2.1-5)
trixie: resolved (fixed in 3.2.1-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza
bugzilla·2016-12-12·CVSS 5.4
CVE-2016-9928 [MEDIUM] CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza
CVE-2016-9928 mcabber: remote attackers can modify the roster and intercept messages via a crafted roster-push IQ stanza
It was discovered that MCabber versions 1.0.3 and before are vulnerable to an attack identical to Gajim's CVE-2015-8688 that can lead to a malicious actor MITMing a conversation, or adding themselves as an entity on a third parties roster (thereby granting themselves the associated privileges).
Upstream patch:
https://bitbucket.org/McKael/mcabber-crew/commits/6e1ead98930d7dd0a520ad17c720ae4908429033/raw
References:
https://gultsch.de/gajim_roster_push_and_message_interception.html
http://seclists.org/oss-sec/2016/q4/653
Discussion:
Created mcabber tracking bugs for this issue:
Affects: fedora-all [bug 1403792]
---
mcabber 1.0.4 has already arrived to stable in
Bugzilla
CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 libarchive: various flaws [epel-5]
bugzilla·2016-10-17·CVSS 7.5
CVE-2016-8687 [HIGH] CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 libarchive: various flaws [epel-5]
CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 libarchive: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Bugzilla
libarchive: various flaws [fedora-all]
bugzilla·2016-10-17·CVSS 7.5
[HIGH] libarchive: various flaws [fedora-all]
libarchive: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug has
Bugzilla
CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 libarchive3: various flaws [epel-6]
bugzilla·2016-10-17·CVSS 7.5
CVE-2016-8687 [HIGH] CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 libarchive3: various flaws [epel-6]
CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 libarchive3: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 mingw-libarchive: various flaws [fedora-all]
bugzilla·2016-10-17·CVSS 7.5
CVE-2016-8687 [HIGH] CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 mingw-libarchive: various flaws [fedora-all]
CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 mingw-libarchive: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2016-8688 libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c) [fedora-all]
bugzilla·2016-09-23·CVSS 5.5
CVE-2016-8688 [MEDIUM] CVE-2016-8688 libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c) [fedora-all]
CVE-2016-8688 libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2016-8688 libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c)
bugzilla·2016-09-21·CVSS 5.5
CVE-2016-8688 [MEDIUM] CVE-2016-8688 libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c)
CVE-2016-8688 libarchive: heap based buffer overflow in detect_form (archive_read_support_format_mtree.c)
Bookkeeping errors when extending the read-ahead buffer when trying
to identify an mtree archive could lead libarchive to significantly
overcalculate the size of the line being read, resulting in heap
out-of-bounds reads or a crash.
Disclosed on oss-security:
http://seclists.org/oss-sec/2016/q3/516
Upstream issue:
https://github.com/libarchive/libarchive/issues/747
Upstream fix:
https://github.com/libarchive/libarchive/commit/eec077f
All the mtree-related crashes in the oss-sec post came from the same
underlying issue and were resolved in this commit.
Discussion:
This could conceivably be exploited for controlled read of the heap, but code execution is not possible.
---
Cr
http://lists.opensuse.org/opensuse-updates/2016-12/msg00027.htmlhttp://www.openwall.com/lists/oss-security/2016/10/16/11http://www.securityfocus.com/bid/93781https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-heap-based-buffer-overflow-in-bid_entry-archive_read_support_format_mtree-c/https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-heap-based-buffer-overflow-in-detect_form-archive_read_support_format_mtree-c/https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-memory-corruptionunknown-crash-in-bid_entry-archive_read_support_format_mtree-c/https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-use-after-free-in-bid_entry-archive_read_support_format_mtree-c/https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-use-after-free-in-detect_form-archive_read_support_format_mtree-c/https://bugzilla.redhat.com/show_bug.cgi?id=1377923https://github.com/libarchive/libarchive/commit/eec077f52bfa2d3f7103b4b74d52572ba8a15acahttps://lists.debian.org/debian-lts-announce/2018/11/msg00037.htmlhttps://security.gentoo.org/glsa/201701-03http://lists.opensuse.org/opensuse-updates/2016-12/msg00027.htmlhttp://www.openwall.com/lists/oss-security/2016/10/16/11http://www.securityfocus.com/bid/93781https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-heap-based-buffer-overflow-in-bid_entry-archive_read_support_format_mtree-c/https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-heap-based-buffer-overflow-in-detect_form-archive_read_support_format_mtree-c/https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-memory-corruptionunknown-crash-in-bid_entry-archive_read_support_format_mtree-c/https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-use-after-free-in-bid_entry-archive_read_support_format_mtree-c/https://blogs.gentoo.org/ago/2016/09/11/libarchive-bsdtar-use-after-free-in-detect_form-archive_read_support_format_mtree-c/https://bugzilla.redhat.com/show_bug.cgi?id=1377923https://github.com/libarchive/libarchive/commit/eec077f52bfa2d3f7103b4b74d52572ba8a15acahttps://lists.debian.org/debian-lts-announce/2018/11/msg00037.htmlhttps://security.gentoo.org/glsa/201701-03
2017-02-15
Published